Severity
5.4MEDIUM
EPSS
0.2%
top 56.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 24

Description

IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5ibm/financial_transaction_manager3.2.03.2.8

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xv9g-pwqj-hpwc: IBM Financial Transaction Manager 32022-05-24
CVEList
CVE-2020-5000: IBM Financial Transaction Manager 32021-06-15
GHSA
Server-side Request Forgery (SSRF) via img tags in reportlab2021-03-29

💥Exploits & PoCs

2
Exploit-DB
BearFTP 0.1.0 - 'PASV' Denial of Service2020-02-03
Exploit-DB
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution2020-01-10

📋Vendor Advisories

26
Chrome
Stable Channel Update for Desktop: CVE-2021-305322021-05-25
Chrome
Stable Channel Update for Desktop: CVE-2021-212282021-04-26
Chrome
Stable Channel Update for Desktop: CVE-2021-211682021-03-02
Red Hat
python-reportlab: Server-side request forgery via img tags2021-02-18
Chrome
Stable Channel Update for Desktop: CVE-2021-211452021-02-02
CVE-2020-5000 (MEDIUM CVSS 5.4) | IBM Financial Transaction Manager 3 | cvebase.io